ZITADEL race condition in lockout policy execution
CVE-2023-47111
What is CVE-2023-47111?
The ZITADEL Identity Infrastructure allows administrators to set a Lockout Policy that limits the number of failed password attempts. However, due to a flaw in its implementation, an attacker can execute multiple simultaneous password checks, effectively circumventing the intended limits of the Lockout Policy. This vulnerability could lead to unauthorized access attempts, increasing the risk of successful attacks against user accounts. The issue has been addressed in versions 2.40.5 and 2.38.3, which include patches to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
zitadel >= 2.39.0, < 2.40.5 < 2.39.0, 2.40.5
zitadel < 2.38.3 < 2.38.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
